Impact
The Listdom WordPress plugin contains a missing authorization flaw that allows attackers to bypass the intended access control safeguards. This breach can enable an attacker to read or alter content managed by Listdom, effectively giving elevated privileges within the WordPress site. The weakness maps to CWE-862 – Missing Authorization.
Affected Systems
The vulnerability affects Webilia Inc.'s Listdom plugin version 5.0.1 and earlier on any WordPress installation. Users who rely on Listdom for managing listings are at risk if they use these outdated plugin versions.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate risk. With an EPSS of less than 1% and no listing in the CISA KEV, the likelihood of public exploitation appears low at present. Nonetheless, because Listdom functions are exposed through the web interface, an attacker with network access could craft requests to trigger the privilege‑bypass, especially if they have the ability to identify the specific endpoints.
OpenCVE Enrichment